Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects execution of a specific msaRAT MSI custom action that loads an embedded lib.dll payload from the MSI Binary table into memory via msiexec.exe during the InstallFinalize phase.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
002
Detects the loading of potential Bring Your Own Vulnerable Driver (BYOVD) drivers, specifically those known to be utilized for bypassing endpoint security controls. This rule triggers on specific driver filenames or drivers loaded from non-standard, user-writable directories (e.g., %TEMP%, Public), which are common tactics for dropping and executing malicious kernel-mode code.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
002
Detects the use of curl.exe to download an MSI file (update_ms.msi) from a remote HTTPS source into the ProgramData directory. This pattern is commonly observed in malware delivery campaigns attempting to deploy payloads in a location with lower access restrictions.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
14018
The following analytic detects the EDRSilencer-specific Windows Filtering Platform filter name "Custom Outbound Filter" when it is configured with a block action.
EDRSilencer creates WFP filters to block outbound traffic from EDR and security agent processes, impairing endpoint telemetry without requiring the tool binary to keep its original process name.
EventCode 5447 identifies creation of the runtime filter with ChangeType %%16384, while EventCode 5441 can show the same persistent filter when the Base Filtering Engine starts.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
006
Detects periodic execution cycles of ERAAgent.exe that involve memory protection changes, characteristic of the SLEEPWALKER malware's XOR-decrypt-execute-reencrypt loop scheduled by a cron-like mechanism.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
203
Detects the loading of compression libraries (such as lzma.dll or 7z.dll) by ERAAgent.exe followed by suspicious process or thread activity (e.g., remote thread creation, memory allocation). This pattern is often associated with the staging and execution of malicious payloads in memory.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
303
Detects ERAAgent.exe (ESET Remote Administrator Agent) interacting with suspicious named pipes (e.g., mojo, spoolss) and attempts to extract credentials from command line parameters, indicating potential credential dumping or lateral movement techniques using the agent process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
203
Detects the ESET Management Agent (ERAAgent.exe) initiating outbound network connections using non-standard socket families, specifically AF_VSOCK (virtual socket) or VMCI (Virtual Machine Communication Interface). These interfaces are typically used for inter-process communication between a host and a guest virtual machine, or between guest virtual machines, and may indicate malicious activity such as lateral movement from a virtualized environment, virtual machine escape attempts, or unauthorized communication within an ESXi host environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
103
Detects the execution of MEGAsync binaries (MEGAsync.exe, MEGAupdater.exe, or MEGAsyncSetup64.exe) from suspicious locations typically used for staging (Temp, Downloads, Public folders), or the creation of MEGAsync configuration and state cache files in the local AppData directory. This pattern is consistent with an adversary setting up a legitimate cloud storage client for data exfiltration.
avatar
Renata Cardoso@rcardososec
avatar
Detections.ai Community
2 months ago
206
Detects a high volume of file rename events initiated by a single process on a device within a short time window (5 minutes). This behavior is often indicative of ransomware activity, where files are renamed as part of the encryption or extortion process.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
2 months ago
12012
This is about the article "Attacking SAM and Extracting Hashes With 7z" from Hackers Arise: https://hackers-arise.com/digital-forensics-attacking-sam-and-extracting-hashes-with-7z/

This query detects instances of 7-Zip executing with elevated administrator privileges on Windows endpoints while filtering out routine background noise. It begins by capturing both live and backfilled process creation telemetry (ProcessRollup2 and SyntheticProcessRollup2) and uses a case-insensitive regular expression to identify any standard 7-Zip executable, including the command-line, GUI, and file manager binaries (7z.exe, 7za.exe, 7zg.exe, or 7zFM.exe). To pinpoint administrative activity, it filters exclusively for processes with a high integrity level decimal of 12288, indicating the binary was elevated via UAC ("Run as administrator"). It then reduces false positives by excluding automated service accounts ending in svc, Active Directory machine accounts ending in $, and the built-in SYSTEM identity. Finally, it formats the remaining high-fidelity events into a structured table displaying the timestamp, executable path, username, integrity level, and full command-line arguments for quick triage.
avatar
Lightkun Yagami@lightkun_CrowdStriker
avatar
CrowdStrikers
2 months ago
17021
This rule performs a two-layer hunt for the ShieldBreak/RoguePlanet (CVE-2026-50656) exploit. Layer 1 detects potential privilege escalation by identifying Windows Error Reporting processes (WerFault, WerFaultSecure, or WerMgr) running as SYSTEM that initiate suspicious child processes like cmd.exe, powershell.exe, or rundll32.exe. Layer 2 identifies the presence of known exploit artifacts including 'ShieldBreak.exe', 'Warden.dll', and the 'eicar_com.zip' test file via process execution or file creation events.
avatar
Lenny Post@LennyPost
avatar
Detection & Hunting Community
2 months ago
1282189
This rule detects cross-process injection techniques, such as OpenProcess, CreateRemoteThread, and memory modifications, specifically targeting 'svchost.exe' instances that do not appear to be hosting critical Windows services. By filtering out known critical services (e.g., RpcSs, DcomLaunch), the rule flags suspicious attempts to inject code into legitimate service host processes to mask malicious activity.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
102
This rule detects in-memory patching of critical Windows security functions, specifically AmsiScanBuffer (used by AMSI) and EtwEventWrite (used by ETW). It monitors for suspicious API calls such as VirtualProtect, WriteProcessMemory, NtProtectVirtualMemory, or NtWriteVirtualMemory targeting these specific DLLs (amsi.dll and ntdll.dll), which is a common technique used by malware and offensive security tools to blind endpoint security and logging mechanisms.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
102
This rule detects in-memory patching of critical Windows security functions, specifically AmsiScanBuffer (used by AMSI) and EtwEventWrite (used by ETW). It monitors for suspicious API calls such as VirtualProtect, WriteProcessMemory, NtProtectVirtualMemory, or NtWriteVirtualMemory targeting these specific DLLs (amsi.dll and ntdll.dll), which is a common technique used by malware and offensive security tools to blind endpoint security and logging mechanisms.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
202
Correlates a Sysmon DriverLoad event matching known BTR.sys hashes with a subsequent System-process (PID 4) deletion of specific Defender binaries or WdFilter/WinDefend registry keys within a 10-second window — the definitive Defender self-destruction signature of the kernel primitive.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6112
Detects outbound HTTP traffic indicative of pyCodeVx RAT check-in behavior. The rule identifies communication with ddnsfree.com C2 domains or requests containing the 'pyCodeVx' marker in the URL or User-Agent, coupled with a base64-encoded, fixed-format victim/session ID.
avatar
Renata Cardoso@rcardososec
avatar
Detections.ai Community
1 month ago
203
Detects modification of autostart extensibility point (ASEP) in registry. Adversaries may modify these keys to execute malicious code when Office files are opened.
There are various legitimate add-ins that also use these keys and this filter list might not be exhaustive.
Thus, it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
002
Detects msedge.exe launched headless (--headless / --headless=new) with CDP remote debugging enabled (--remote-debugging-port=), a temp profile directory matching the launcher-edge- naming pattern, and window flags positioning it off-screen (--window-position=-32000,-32000, --window-size=1,1). This combination matches the TWINLOOT implant's technique of spawning a headless Edge instance with a Chrome DevTools Protocol connection, using the browser's authenticated same-origin session to proxy Microsoft Graph API C2 traffic so it blends in with legitimate browser network activity while remaining invisible on-screen. Excludes known browser-automation/CI framework parent processes and the --enable-automation flag to reduce false positives.
references:
- https://detections.ai/inspirations/01a01ade-da64-7718-8281-426118171583
- https://detections.ai/inspirations/01a01ade-d9a6-742d-8e2f-f60b5efce416
- https://detections.ai/inspirations/01a01ade-da04-700d-ba14-769eef28e475
- https://github.com/ontinue-research/threat-intel-iocs/blob/main/Public/2026-07-27-TWINLOOT-IOCs.md
- https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
4015
Detects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
2 months ago
3025
The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory.
These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
000
Page 449 of 1870